Forum Moderators: open

Message Too Old, No Replies

NetSky.C

Is it just me or does it like everyone else as much?

         

Stefan

6:59 pm on Mar 1, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I've been receiving what I guess to be Netsky.C emails starting at once a day last mid-week, now up to 6 times a day. The subjects, and simple varying one line text, with a .zip attachment, seem to match the description of Netsky.C. It's coming to my website-posted email addy. so I guess it's got me from the ODP or an email harvester.

In the past I've occasionally had virus infection attempts, but this one is astoundingly busy. I configured Outlook yesterday to block .zips just in case I accidentally click the wrong thing, while I'm deleting them, and open the attachment.

Are others seeing an incredible amount of activity from this thing?

[edited by: lawman at 7:57 pm (utc) on Mar. 1, 2004]

Not a problem, lawman... :-) I wondered at first, when I saw the edit, if I was somehow inviting major traffic to the site on a search of it, and eating up WW bandwidth...

[edited by: Stefan at 8:37 pm (utc) on Mar. 1, 2004]

bcolflesh

8:06 pm on Mar 1, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I'm unsure why the name is snipped - is it an actual company?

trendmicro.com/vinfo/virusencyclo/default2.asp?m=a&virus=netsky&alt=netsky&key=netsky&payload=&type=&day=&month=&year=&wkday=

Stefan

8:08 pm on Mar 1, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Sorry, mods...

I take it that the specific would have caused problems. I shall be more circumspect in the future.

lawman

8:17 pm on Mar 1, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



<sheepish> My bad. My mod genes kicked in before I had a chance to recognize that you were talking about the NetSky virus. I don't know of any NetSky company. Stefan, feel free to replace the "<snip>" with your own words. </sheepish>

lawman

troels nybo nielsen

8:44 am on Mar 2, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I'm getting them too, Stefan. And I just was warned by the Norton filter at a local school that they had received an infected email from me. I know the name of the guy that the email was sent to, but he is certainly not in my address book and my computer is not infected. Does anyone know how sender addresses are spoofed? Are they taken from address books in the infected computers or are they taken from some central data base?

Hehe lawman, the guys will never let you forget that one.

gethan

10:54 am on Mar 2, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Yep - it spoofs alright.

I'm filtering a huge number of these - (ok 50ish today - but when I only now get around 50ish spam filtered thats huge).

I'm getting:

Mail delivery blocked replies.
Mail delivery failure replies
The virus itself.

Look at the headers and you'll find the IP of the machine that is infected but no way to contact the person.

Good news - tomorrow morning the virus is set to make the speakers beep continously - hopefully it will be irritating enough to make them clean up PCs. My computer (linux) is already beeping continously due to the beep when mail arrives - Mozilla should really not beep when it falls into my junk mail folder.

More reading: Popular press ;)

[theregister.co.uk...]

Stefan

2:18 pm on Mar 2, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Knock on wood, but it seems to be easing off. I didn't get any overnight. From what I've read, a few new variants have been showing up in the last couple of days... let's hope this isn't just a lull in the storm.

The beeping is a nice touch. Maybe some of the infected people will start realizing that their computers have been turned into drones.

gethan

5:02 pm on Mar 2, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



[news.bbc.co.uk...]

The biggest virus outbreak apparently...

Stefan

5:16 pm on Mar 2, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



All the attachments I'm getting are .zip, (another one came in an hour ago).

Maybe it's bagle that I'm getting.

Stefan

1:31 am on Mar 3, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



The subject of the thread was changed to "Pesky", and it's gone beyond pesky for me.

I've blocked, in Outlook 2000 SP3, the dozens of .zip attachments that I've been getting the last few days, but I'm also getting a few emails that have no attachments, but have originating addys and subjects that look dodgy as hell. I've been deleting them unopened, but I'm a little concerned about dumping legit emails in the process.

Do any of the brilliant minds here know if there are any variants, out and about, that can infect without attachments? (I have scripting disabled). These dodgy non-attachment emails use the same subjects like, "Info", as the attachment ones. They started at the same time as the Netsky .zip stuff. I don't know if they're just botched attempts or something even sneakier.

[edited by: lawman at 1:53 am (utc) on Mar. 3, 2004]
[edit reason] Spliced Post [/edit]

g1smd

3:26 pm on Mar 3, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I spent the whole day, yesterday, removing viruses from a friend's computer. It only takes one accidental click for the little blighters to start to take over.

Norton have some good "one virus" removal tools for free download. The evil virus crashed their tool three times while trying to take all these copies out, but eventually got the job done.

HughMungus

6:42 pm on Mar 3, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Every day. I now send all email with attachments straight to the trash.